---
title: "Readiness & Maturity Assessment"
description: "Run a pre-engagement PCI DSS maturity interview that scores each control 0–5 and produces a gap-to-green readiness report — before the formal ROC begins."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Readiness & Maturity Assessment

Before the formal Report on Compliance begins, Kliper lets you run a **Readiness Assessment** — a short, interview-based maturity review that scores a client's PCI DSS posture on a **0–5 scale per control** and produces a one-page **gap-to-green report** for the board. It's the pre-engagement conversation that tells everyone where the client stands and what to fix first.

The scoring is **deterministic and assessor-driven** — you rate the depth of each answer; Kliper does not invent a score. The result is a repeatable maturity snapshot, not an AI guess.

## Where to find it

Open a client from the **Engagement Hub → Clients**, then select the **Readiness** tab. The tab lists every readiness assessment for that client with its signal count, overall maturity, and status. Click **New assessment** to start an interview, or open an existing one.

## The maturity scale

Every control is scored on a fixed 0–5 scale. The colors are a **scoring semantic** (they mean the same thing everywhere in the product), not branding.

| Level | Name | Meaning |
| --- | --- | --- |
| **0** | Non-existent | No process; the control is absent. |
| **1** | Initial | Ad-hoc, undocumented, inconsistent. |
| **2** | Established | Documented and performed, but not consistently. |
| **3** | Defined | Standardized, documented, and consistently followed. |
| **4** | Managed | Measured and monitored; deviations are caught. |
| **5** | Optimized | Continuously improved; evidence is automatic. |

**Defined (3)** is the target line — a domain scoring below Defined becomes a **lever** you author a next action for at sign-off (see [Closing the session](#closing-the-session)).

## Running the interview

Starting a new assessment opens the **Readiness Interview**. It's built for a live conversation — score with the keyboard while you talk.

1. **Pick a control**

   The center panel shows the current control — its number, requirement, and the question. Use the left rail to filter by **dimension** (Controls, Validation, Evidence, Governance, General) or jump to a requirement (R1–R12). Each requirement row shows how many of its controls you've covered.
2. **Capture the answer**

   Optionally type what the interviewee described — observations, evidence references, or gaps — in the **Notes / Evidence cited** field. This is captured with the signal and feeds the report's current-state notes.
3. **Score the maturity**

   Choose a level **0–5** — the score rates the *depth of the answer*, not the question. Press the number keys <kbd>0</kbd>–<kbd>5</kbd> to select, then <kbd>Enter</kbd> to record and advance to the next unanswered control. Arrow keys move between controls.

> **Note**
>
> **Jump to any control** — click the `N of M · Dimension · Rx` counter above the arrows to open a searchable list of every control in the current queue. Type a control number (e.g. `1.3.1`) to jump straight to it; recorded controls show their level.

### The live compass

Across the top, the **compass** updates from the scoring engine as you record signals:

- **Overall maturity** — the rolled-up 0–5.0 score and its tier.
- **Maturity distribution** — where each domain sits on the 0–5 band, with the overall marker.
- **Weakest domain** — the lowest-scoring requirement (click to jump to it).
- **Coverage** — signals recorded and domains covered.

### Ad-hoc observations

Not every finding maps to a scripted control. Click **Ad-hoc observation** to record an off-script signal — a maturity level plus a short note — that rolls into the domain you assign it to.

> **Tip**
>
> The interview scores controls the client can be assessed on. The bank carries a maturity question for **236 of ~264** PCI DSS v4.0.1 controls; the rest aren't scored here, which is why coverage tops out below the full control count. A footnote on the requirement rail states this.

## Closing the session

When the conversation is done, click **Close session** to open the **sign-off** dialog.

For each **lever** — the lowest-scoring dimension in a domain that sits below **Defined (3)** — you author the concrete **next action** that would raise it a level. The current-state note is carried from the interview; the action is yours. Blank actions are skipped, and if every assessed domain is already at Defined or above there are no levers to author.

> **Caution**
>
> **Closing locks the scoring and makes the report final.** Reopen the session from the interview header if you need to change a score afterward.

## The readiness report

From the interview (or the assessment row), open the **Report** — the client-facing deliverable. It renders from the same engine snapshot, so the numbers always match the interview:

- **Overall posture** — the maturity tier and the 0–5 distribution.
- **Domain scores** — average maturity per requirement (R1–R12).
- **Maturity matrix** — a requirement × dimension grid of every recorded cell.
- **Gap-to-green** — the ranked levers, each showing its current level, target level, and the next action you authored.

While the session is open the report is a **Draft** (a "provisional — session in progress" banner shows and figures update live). After you close the session it becomes **Final**. Use **Export PDF** to produce a print-ready copy for the client.

> **Note**
>
> The readiness report is the natural output of Kliper's **Cyber Pulse** free tier — the one-page "where do we stand" answer a prospect gets from a single 45-minute conversation, before any formal engagement.

Source: https://docs.kliper.dev/guides/readiness-maturity/index.mdx
